Channels
android_tests
apple-silicon
arm-architecture
auditing-warroom
aws
carving
code-review
community-feeds
core
darkbytes
doorman
ebpf
eclecticiq-polylogyx-extension
extensions
file-carving
fim
fleet
fleet-dev
fleetosquery
foundation
fuzzing
general
golang
goquery
infrastructure
jobs
kolide
linen-dev
linux
macos
officehours
osctrl
plugins
process-auditing
querycon
queryhub
random
selfgroup
sql
tls
uptycs
vendor-feeds
website
windows
zeek
zentral
zercurity
Powered by
Title
b
Brandon Mesa
08/12/2022, 4:03 PM
hi all, i'm working on auditing resource utilization on macos endpoints(CPU/memory utilization will suffice for now), would you say osquery is the right tool for this?
z
zwass
08/12/2022, 4:08 PM
Sure, osquery can be useful for this! See
https://zercurity.medium.com/process-monitoring-with-osquery-22c6f38fc239
for some good queries to use and heads up that additional functionality is coming soon in osquery:
https://github.com/osquery/osquery/pull/7597
b
Brandon Mesa
08/12/2022, 4:09 PM
Thanks
@zwass
!
5 Views
#general
Join Slack